Friday, November 09, 2012

Ubuntu - Nagios Installation

This guide is intended to provide you with simple instructions on how to install Nagios from source (code) on Ubuntu and have it monitoring your local machine inside of 20 minutes. No advanced installation options are discussed here - just the basics that will work for 95% of users who want to get started.

These instructions were written based on an Ubuntu 6.10 (desktop) installation. They should work for an Ubuntu 7.10 install as well. I used a virtual machine running Ubuntu JeOS back in 2009.

If you follow these instructions, here's what you'll end up with:

Nagios and the plugins will be installed underneath /usr/local/nagios
Nagios will be configured to monitor a few aspects of your local system (CPU load, disk usage, etc.)
The Nagios web interface will be accessible at http://localhost/nagios/

Required Packages

Make sure you've installed the following packages on your Ubuntu installation before continuing.

Apache 2
GCC compiler and development libraries
GD development libraries
You can use apt-get to install these packages by running the following commands:

sudo apt-get install apache2
sudo apt-get install build-essential


With Ubuntu 6.10, install the gd2 library with this command:

sudo apt-get install libgd2-dev

With Ubuntu 7.10, the gd2 library name has changed, so you'll need to use the following:

sudo apt-get install libgd2-xpm-dev

1) Create Account Information

Become the root user.

sudo -s

Create a new nagios user account and give it a password.

/usr/sbin/useradd nagios
passwd nagios


On Ubuntu server edition (6.01 and possible newer versions), you will need to also add a nagios group (it's not created by default). You should be able to skip this step on desktop editions of Ubuntu.

/usr/sbin/groupadd nagios
/usr/sbin/usermod -G nagios nagios


Create a new nagcmd group for allowing external commands to be submitted through the web interface. Add both the nagios user and the apache user to the group.

/usr/sbin/groupadd nagcmd
/usr/sbin/usermod -G nagcmd nagios
/usr/sbin/usermod -G nagcmd www-data


2) Download Nagios and the Plugins

Create a directory for storing the downloads.

mkdir ~/downloads
cd ~/downloads


Download the source code tarballs of both Nagios and the Nagios plugins (visit http://www.nagios.org/download/ for links to the latest versions). At the time of writing, the latest versions of Nagios and the Nagios plugins were 3.0 and 1.4.11, respectively.


wget http://prdownloads.sourceforge.net/nagios/nagios-3.0.1.tar.gz
wget http://osdn.dl.sourceforge.net/sourceforge/nagiosplug/nagios-plugins-1.4.11.tar.gz



3) Compile and Install Nagios

Extract the Nagios source code tarball.

cd ~/downloads
tar xzf nagios-3.0.tar.gz
cd nagios-3.0


Run the Nagios configure script, passing the name of the group you created earlier like so:

./configure --with-command-group=nagcmd

Compile the Nagios source code.

make all


Install binaries, init script, sample config files and set permissions on the external command directory.

make install
make install-init
make install-config
make install-commandmode


Don't start Nagios yet - there's still more that needs to be done...

4) Customize Configuration

Sample configuration files have now been installed in the /usr/local/nagios/etc directory. These sample files should work fine for getting started with Nagios. You'll need to make just one change before you proceed...

Edit the /usr/local/nagios/etc/objects/contacts.cfg config file with your favorite editor and change the email address associated with the nagiosadmin contact definition to the address you'd like to use for receiving alerts.

vi /usr/local/nagios/etc/objects/contacts.cfg

5) Configure the Web Interface

Install the Nagios web config file in the Apache conf.d directory.

make install-webconf

Create a nagiosadmin account for logging into the Nagios web interface. Remember the password you assign to this account - you'll need it later.

htpasswd -c /usr/local/nagios/etc/htpasswd.users nagiosadmin

Restart Apache to make the new settings take effect.

/etc/init.d/apache2 reload

6) Compile and Install the Nagios Plugins

Extract the Nagios plugins source code tarball.

cd ~/downloads
tar xzf nagios-plugins-1.4.11.tar.gz
cd nagios-plugins-1.4.11


Compile and install the plugins.

./configure --with-nagios-user=nagios --with-nagios-group=nagios
make
make install


7) Start Nagios

Configure Nagios to automatically start when the system boots.

ln -s /etc/init.d/nagios /etc/rcS.d/S99nagios

Verify the sample Nagios configuration files.

/usr/local/nagios/bin/nagios -v /usr/local/nagios/etc/nagios.cfg

If there are no errors, start Nagios.

/etc/init.d/nagios start

8) Login to the Web Interface

You should now be able to access the Nagios web interface at the URL below. You'll be prompted for the username (nagiosadmin) and password you specified earlier.

http://localhost/nagios/

Click on the "Service Detail" navbar link to see details of what's being monitored on your local machine. It will take a few minutes for Nagios to check all the services associated with your machine, as the checks are spread out over time.

9) Other Modifications

If you want to receive email notifications for Nagios alerts, you need to install the mailx (Postfix) package.

sudo apt-get install mailx

You'll have to edit the Nagios email notification commands found in /usr/local/nagios/etc/objects/commands.cfg and change any '/bin/mail' references to '/usr/bin/mail'. Once you do that you'll need to restart Nagios to make the configuration changes live.

sudo /etc/init.d/nagios restart


Configuring email notifications is outside the scope of this documentation. Refer to your system documentation, search the web, or look to the NagiosCommunity.org wiki for specific instructions on configuring your Ubuntu system to send email messages to external addresses.

Ubuntu 101

From old Yahoo Notes I found this good intro to Ubuntu VMs.

Logs: A "live" view of a logfile on Linux

tail -f /path/thefile.log

Storage: Adding Hard drive

jblanco@us01:~$ sudo fdisk -l

Disk /dev/sda: 10.7 GB, 10737418240 bytes
255 heads, 63 sectors/track, 1305 cylinders
Units = cylinders of 16065 * 512 = 8225280 bytes

Device Boot Start End Blocks Id System
/dev/sda1 * 1 1247 10016496 83 Linux
/dev/sda2 1248 1305 465885 5 Extended
/dev/sda5 1248 1305 465853+ 82 Linux swap / Solaris

Disk /dev/sdb: 42.9 GB, 42949672960 bytes
255 heads, 63 sectors/track, 5221 cylinders
Units = cylinders of 16065 * 512 = 8225280 bytes

Disk /dev/sdb doesn't contain a valid partition table
jblanco@us01:~$ fdisk /dev/sdb

Unable to open /dev/sdb
jblanco@us01:~$ sudo fdisk /dev/sdb
Device contains neither a valid DOS partition table, nor Sun, SGI or OSF disklabel
Building a new DOS disklabel. Changes will remain in memory only,
until you decide to write them. After that, of course, the previous
content won't be recoverable.

The number of cylinders for this disk is set to 5221.
There is nothing wrong with that, but this is larger than 1024,
and could in certain setups cause problems with:
1) software that runs at boot time (e.g., old versions of LILO)
2) booting and partitioning software from other OSs
(e.g., DOS FDISK, OS/2 FDISK)
Warning: invalid flag 0x0000 of partition table 4 will be corrected by w(rite)

Command (m for help): m
Command action
a toggle a bootable flag
b edit bsd disklabel
c toggle the dos compatibility flag
d delete a partition
l list known partition types
m print this menu
n add a new partition
o create a new empty DOS partition table
p print the partition table
q quit without saving changes
s create a new empty Sun disklabel
t change a partition's system id
u change display/entry units
v verify the partition table
w write table to disk and exit
x extra functionality (experts only)

Command (m for help): n
Command action
e extended
p primary partition (1-4)
p
Partition number (1-4): 1
First cylinder (1-5221, default 1):
Using default value 1
Last cylinder or +size or +sizeM or +sizeK (1-5221, default 5221):
Using default value 5221

Command (m for help): t
Selected partition 1
Hex code (type L to list codes): L

0 Empty 1e Hidden W95 FAT1 80 Old Minix be Solaris boot
1 FAT12 24 NEC DOS 81 Minix / old Lin bf Solaris
2 XENIX root 39 Plan 9 82 Linux swap / So c1 DRDOS/sec (FAT-
3 XENIX usr 3c PartitionMagic 83 Linux c4 DRDOS/sec (FAT-
4 FAT16 <32M 40 Venix 80286 84 OS/2 hidden C: c6 DRDOS/sec (FAT-
5 Extended 41 PPC PReP Boot 85 Linux extended c7 Syrinx
6 FAT16 42 SFS 86 NTFS volume set da Non-FS data
7 HPFS/NTFS 4d QNX4.x 87 NTFS volume set db CP/M / CTOS / .
8 AIX 4e QNX4.x 2nd part 88 Linux plaintext de Dell Utility
9 AIX bootable 4f QNX4.x 3rd part 8e Linux LVM df BootIt
a OS/2 Boot Manag 50 OnTrack DM 93 Amoeba e1 DOS access
b W95 FAT32 51 OnTrack DM6 Aux 94 Amoeba BBT e3 DOS R/O
c W95 FAT32 (LBA) 52 CP/M 9f BSD/OS e4 SpeedStor
e W95 FAT16 (LBA) 53 OnTrack DM6 Aux a0 IBM Thinkpad hi eb BeOS fs
f W95 Ext'd (LBA) 54 OnTrackDM6 a5 FreeBSD ee EFI GPT
10 OPUS 55 EZ-Drive a6 OpenBSD ef EFI (FAT-12/16/
11 Hidden FAT12 56 Golden Bow a7 NeXTSTEP f0 Linux/PA-RISC b
12 Compaq diagnost 5c Priam Edisk a8 Darwin UFS f1 SpeedStor
14 Hidden FAT16 `/mnt/disk/home'
`/home/jblanco' -> `/mnt/disk/home/jblanco'
`/home/jblanco/.bashrc' -> `/mnt/disk/home/jblanco/.bashrc'
`/home/jblanco/.bash_profile' -> `/mnt/disk/home/jblanco/.bash_profile'
`/home/jblanco/.bash_logout' -> `/mnt/disk/home/jblanco/.bash_logout'
`/home/jblanco/.sudo_as_admin_successful' -> `/mnt/disk/home/jblanco/.sudo_as_admin_successful'
`/home/jblanco/.bash_history' -> `/mnt/disk/home/jblanco/.bash_history'
`/home/jblanco/downloads' -> `/mnt/disk/home/jblanco/downloads'
jblanco@us01:~$ cd /mnt/disk
jblanco@us01:~$ cd /mnt/disk
jblanco@us01:/mnt/disk$ ls
home lost+found

GNU nano 1.3.10 File: /etc/fstab
# /etc/fstab: static file system information.
#
#
proc /proc proc defaults 0 0
/dev/sda1 / ext3 defaults,errors=remount-ro 0 1
/dev/sda5 none swap sw 0 0
/dev/sdb1 /nas ext3 defaults 0 0
/dev/hdc /media/cdrom0 udf,iso9660 user,noauto 0 0
/dev/fd0 /media/floppy0 auto rw,user,noauto 0 0

jblanco@us01:/nas$ sudo chown -R jblanco:jblanco /nas
jblanco@us01:/nas$ sudo chmod -R 755 /nas

Repository: Change from CD-ROM to Internet

There's an easy way to fix this problem. Run the following command to open the sources.list file. You can use a different editor if you feel like.

sudo vi /etc/apt/sources.list

The first thing you'll want to do is comment out this line, by placing a # symbol before it.

deb cdrom:[Ubuntu-Server 6.10 _Ed…..

You can also use this opportunity to uncomment the universe repositories.

Now that you've updated the repository list, you will have to run this command to update the local list of available software:

sudo apt-get update

Now you can apt-get install from the internet.


Packages: See What Version of a Package Is Installed on Ubuntu


dpkg -s

See Where a Package is Installed on Ubuntu

dpkg -L
dpkg -l


Disk: List disk space usage on Ubuntu

df -Th

Ubuntu Networking: From Dynamic To Static

Hercules System/370, ESA/390, and z/Architecture Emulator on Debian

Hercules is an open source software implementation of the mainframe System/370 and ESA/390 architectures, in addition to the new 64-bit z/Architecture. Hercules runs under Linux, Windows (98, NT, 2000, and XP), Solaris, FreeBSD, and Mac OS X (10.3 and later). Back in 2009 I was able to play around with the Hercules emulator and Debian zLinux/390.

$ mkdir zlinux
$ cd zlinux
$ mkdir dasd rdr prt

$ cd rdr
$ wget http://ftp.nl.debian.org/debian/dists/etch/main/installer-s390/current/images/generic/initrd.debian
$ wget http://ftp.nl.debian.org/debian/dists/etch/main/installer-s390/current/images/generic/kernel.debian
$ wget http://ftp.nl.debian.org/debian/dists/etch/main/installer-s390/current/images/generic/parmfile.debian

$ dasdinit -lfs -linux 3390.LINUX.0120 3390-3 LIN120  # /
$ dasdinit -lfs -linux 3390.LINUX.0121 3390-3 LIN121  # /home

# hercules -f s390.cnf



zlinux/s390.cnf

CPUSERIAL 000069        # CPU serial number
CPUMODEL  9672          # CPU model number
MAINSIZE  256           # Main storage size in megabytes.
XPNDSIZE  0             # Expanded storage size in megabytes
CNSLPORT  3270          # TCP port number to which consoles connect
NUMCPU    1             # Number of CPUs
LOADPARM  0120....      # IPL parameter
OSTAILOR  LINUX         # OS tailoring
PANRATE   SLOW          # Panel refresh rate (SLOW, FAST)
ARCHMODE  ESAME         # Architecture mode ESA/390 or ESAME

#
#  Device Definitions
#
# .-----------------------Device number
# |     .-----------------Device type
# |     |       .---------File name and parameters
# |     |       |
# V     V       V
#---    ----    --------------------

# console
001F    3270

# terminal
0009    3215

# reader
000C    3505    ./rdr/kernel.debian ./rdr/parmfile.debian ./rdr/initrd.debian autopad eof

# printer
000E    1403    ./prt/print00e.txt crlf

# dasd
0120    3390    ./dasd/3390.LINUX.0120
0121    3390    ./dasd/3390.LINUX.0121

# tape
0581    3420

# network                               s390     realbox
0A00,0A01  CTCI -n /dev/net/tun -t 1500 192.168.1.189 192.168.1.188



# iptables -t nat -A POSTROUTING -o eth0 -s 10.1.1.0/24 -j MASQUERADE
# iptables -A FORWARD -s 192.168.1.0/24 -j ACCEPT
# iptables -A FORWARD -d 192.168.1.0/24 -j ACCEPT
# echo 1 > /proc/sys/net/ipv4/ip_forward
# echo 1 > /proc/sys/net/ipv4/conf/all/proxy_arp



HMC:

ipl c  Note: This is device 000C - 3505

Primary Network Interface is ctc: Channel to Channel (CTC) or ESCON connection
Enter .1


Define the end-points for this virtual network interface

Select ctc device
Enter .1


Select protocol -s/390
Enter .1


Now, enter the IP addresses for the end-points (must match the IP addresses in the .cnf file).
Enter s390 box IP:

.10.1.1.2

Enter host box IP:

.10.1.1.1



Enter DNS server IP - choose the same your non-virtual system uses (see /etc/resolv.conf):

.x.x.x.x

Enter hostname:

.s390

Enter your domain name; to specify no domain name, you need to enter the empty string, but due to the way Hercules handles input, you will need to enter a dot followed by a space):

.home



Now, just sit back, and wait until your system generates a SSH key. This will take a few minutes.



Before long, the installer will ask you for a password for the remainder of the install process, just enter anything:

.foo


You'll know you are on the right track! Now, open a new terminal, and ssh into installer@10.1.1.2, if everything you did was right, ssh will ask you for a password.
Remember that you are using ssh which encrypts everything, and therefore things will be slow.
Once you enter the right password, a more familiar looking Debian installer will start up:


All done. Reboot at the end of install.

HMC: ipc 120


The system you now have is running with a 31-bit kernel. If you want a 64-bit kernel, simply run:

# aptitude install kernel-image-2.6-s390x

This will install the right image, and set up zIPL (the bootloader) to do the right thing. The original kernel image will remain installed, and you can select it in the bootloader (right after you issue ipl on the Hercules console). Enjoy!

Linux ISOS

Not really related to privacy or security, but I sometimes forget this command, and need to look it up. This way, I'll know exactly where to find it:

To make an ISO from your CD/DVD, place the media in your drive but do not mount it. If it automounts, unmount it.

dd if=/dev/dvd of=dvd.iso # for dvd
dd if=/dev/cdrom of=cd.iso # for cdrom
dd if=/dev/scd0 of=cd.iso # if cdrom is scsi


To make an ISO from files on your hard drive, create a directory which holds the files you want. Then use the mkisofs command.

mkisofs -o /tmp/cd.iso /tmp/directory/

This results in a file called cd.iso in folder /tmp which contains all the files and directories in /tmp/directory/.

Thursday, September 20, 2012

AIX Encryption Notes

Benefits:

  • The encryption is done by the OS, so no application reconfiguration is required

  • The encryption is a feature included with AIX, so it is available at no cost

  • The encryption is performed at the file system level, so encryption for main application could be phased in gradually as they have 8 distinct file systems


Concerns:

  • With the encryption being done on the server side, there are CPU cycles expended to perform the encryption

  • The estimated CPU cost is 2-5%, which is within our current idle usage availability (i.e. no additional CPUs are required in order to implement)

  • There would be downtime required to perform the encryption, but that might be able to be done multi-threaded for main application.


Unknown:

  • The AIX mechanism for encryption is geared to granting access by users and groups; in this case we would be doing group level encryption

  • The encryption key store is unique per user and has a second layer of encryption using the user’s password, so as the user changes their password, their encryption key store is re-encrypted. After the initial encryption key store has been created, an additional step is required once a user’s password changes

  • Do not yet know if processes spawned by a parent process inherit access to the encryption key store; in all likelihood they would – but if not, that would be a showstopper; however initial testing would be able to verify this almost immediately

Thursday, June 07, 2012

Paging Space Utilization

We received this alert this morning.  At the time, the paging space utilization exceeded 80%:

[yo@pd2]/>lsps -a
Page Space      Physical Volume   Volume Group Size %Used Active  Auto  Type Chksum
paging05        hdisk0            rootvg        1024MB     0    no    no    lv     0
paging04        hdisk0            rootvg        1024MB     0    no    no    lv     0
paging03        hdisk0            rootvg        1024MB     0    no    no    lv     0
paging02        hdisk0            rootvg        1024MB    80   yes   yes    lv     0
paging01        hdisk0            rootvg        1024MB    79   yes   yes    lv     0
paging00        hdisk0            rootvg        1024MB    80   yes   yes    lv     0
hd6             hdisk0            rootvg        1024MB    80   yes   yes    lv     0


There is normally 4GB of paging space active, plus there is another 3GB standing by.  Occasionally AIX paging space will become filled with stale segments, especially when java is in use on the system, which in this case is mostly from WebSphere.  By deactivating and reactivating the active paging spaces, those get cleared out.  Note: it can take up to about 10 minutes per space to deactivate.

For the procedure:
1.    Activate at least one of the spare spaces
a.    swapon /dev/paging05
2.    Step through each of the other active spaces, and issue a swapoff and swapon
a.    swapoff /dev/hd6
b.    swapon  /dev/hd6
c.    swapoff /dev/paging00
d.    swapon  /dev/paging00
e.    swapoff /dev/paging01
f.    swapon  /dev/paging01
g.    swapoff /dev/paging02
h.    swapon  /dev/paging02
3.    Release the standby space(s) activated earlier
a.    swapoff /dev/paging05

Following the procedure, we went from 80% to 5%:

[yo@pd2]/home/yo>lsps -a
Page Space      Physical Volume   Volume Group Size %Used Active  Auto  Type Chksum
paging05        hdisk0            rootvg        1024MB     0    no    no    lv     0
paging04        hdisk0            rootvg        1024MB     0    no    no    lv     0
paging03        hdisk0            rootvg        1024MB     0    no    no    lv     0
paging02        hdisk0            rootvg        1024MB     2   yes   yes    lv     0
paging01        hdisk0            rootvg        1024MB     4   yes   yes    lv     0
paging00        hdisk0            rootvg        1024MB     6   yes   yes    lv     0
hd6             hdisk0            rootvg        1024MB     9   yes   yes    lv     0


Alert:

Subject: ALERT:Warning PctTotalPgSpFree at 19.926 on pd2

Host % Total Paging Space Free PctTotalPgSpFree for pd2 triggered PctTotalPgSpFree < 20 at 19.926

Alert detail:
ERRM_DATA_TYPE=CT_FLOAT64
ERRM_RSRC_CLASS_NAME=Host
ERRM_ATTR_NAME=% Total Paging Space Free
ERRM_COND_SEVERITYID=0
ERRM_NODE_NAMELIST={pd2}
ERRM_COND_NAME=PG_Warning
ERRM_ATTR_PNAME=PctTotalPgSpFree
ERRM_COND_HANDLE=0x6004 0xffff 0xd20fd739 0x873cfd56 0x126a2686 0xfbdb1899
ERRM_RSRC_HANDLE=0x6008 0xffff 0xd20fd739 0x873cfd56 0x122601f8 0x619e2352 ERRM_TYPE=Event
ERRM_ER_HANDLE=0x6006 0xffff 0xd20fd739 0x873cfd56 0x122601f1 0x70eec021
ERRM_RSRC_NAME=pd2
ERRM_RSRC_CLASS_PNAME=IBM.Host
ERRM_ATTR_NUM=1
ERRM_TYPEID=0
ERRM_TIME=1339082122,353161
ERRM_RSRC_TYPE=0
ERRM_COND_SEVERITY=Informational
ERRM_EXPR=PctTotalPgSpFree < 20
ERRM_VALUE=19.926
ERRM_COND_BATCH=0
ERRM_NODE_NAME=pd2
ERRM_ER_NAME=Warning notifications

Wednesday, May 16, 2012

.Trashes, .fseventsd, and .Spotlight-V100

Merely plugging a removable drive into a mac (when it has write access) makes OS/X think it can take the liberty to write a lot of hidden garbage onto that disk. If you want to stop this from happening, you have to put some special files on that disk before you plug it in.

To stop OS/X from doing Spotlight indexing, you need a file called .metadata_never_index in the root directory of the removable drive.

To stop OS/X from making a .Trashes directory, you need to make your own file that *isn’t* a directory and call it .Trashes

To keep it from doing logging of filesystem events on the drive, you need to make a directory called .fseventsd and inside that folder put a single file named no_log

The contents of these files don’t matter, so you can make them empty files using touch. Even better, you could make it a text file with a link to this post, so that you (or someone else) wandering across the files will know what they’re for.

Apple’s choice to do this is incredibly self-serving and shameful. At bare minimum, hidden files and features like these should be off by default for any non-mac-only filesystem formats. They should only be enabled when the user has been made aware of them.